CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2026-79773: winter 0 to before 1.2.13

CVE-2026-79773. CVSS 3.1 base score 4.9 (MEDIUM, Vendor/CNA). EPSS 0.00493 (percentile 0.40255), scored 2026-10-06.

Affected technology

winter · 0 to before 1.2.13
wintercms

Description’s affected range: before 1.2.13

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · High privileges required · No user interaction required

What an attacker can do

Attackers can reference files like .env outside the theme directory, and the combined output served through the combine route becomes readable by unauthenticated visitors, exposing application keys and database credentials. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-22
CCR priority
19.7 /100 (P5)
CVSS 3.1
4.9 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N · Vendor/CNA
EPSS
0.00493 · percentile 0.40365 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-79773.html